[PULL 15/43] hw/arm/ax3000-soc: fix heap overflow from missing class_size

Peter Maydell <[email protected]>
Newsgroups org.nongnu.qemu-devel
Message-ID <[email protected]>
From: Doug Cook <[email protected]>

TYPE_AX3000_SOC declares an Ax3000SoCClass via OBJECT_DECLARE_TYPE() and
ax3000_class_init() writes to it:

    Ax3000SoCClass *sc = AX3000_SOC_CLASS(oc);
    sc->num_cpus = AX3000_NUM_CPUS;

but its TypeInfo omits .class_size, so type_initialize() only allocates
class_size inherited from the parent, i.e. sizeof(SysBusDeviceClass).
The store to sc->num_cpus therefore writes 4 bytes of the value 4 just
past the end of the class allocation, corrupting whatever heap block
follows it.

Fix by setting class_size.

Fixes: 33a71a68c6e1 ("hw/arm: Add Axiado SoC AX3000")
Resolves: https://gitlab.com/qemu-project/qemu/-/work_items/4197
Signed-off-by: Doug Cook <[email protected]>
Message-id: LVXPR21MB70090B04FF7397B0F2A201C8ADA72@LVXPR21MB7009.namprd21.prod.outlook.com
Reviewed-by: Peter Maydell <[email protected]>
Signed-off-by: Peter Maydell <[email protected]>
---
 hw/arm/ax3000-soc.c | 1 +
 1 file changed, 1 insertion(+)

diff --git a/hw/arm/ax3000-soc.c b/hw/arm/ax3000-soc.c
index 71e31c6fb46..ebe174fb978 100644
--- a/hw/arm/ax3000-soc.c
+++ b/hw/arm/ax3000-soc.c
@@ -236,6 +236,7 @@ static const TypeInfo axiado_soc_types[] = {
         .instance_size  = sizeof(Ax3000SoCState),
         .instance_init  = ax3000_init,
         .class_init     = ax3000_class_init,
+        .class_size     = sizeof(Ax3000SoCClass),
     }
 };
 
-- 
2.43.0
lmpx.com only provides a reader for public news (NNTP) servers. It is not affiliated with the servers or forums shown here and is not responsible for the content of articles, which is written by their respective authors.